Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-21504

CVSS 5.5 · Medium EPSS 0.08% · P24
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-21504

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in a use count error that allowed a file descriptor to a socket to be closed and freed while it was still in use by another portion of the kernel. An attack with local access can operate on the socket, and cause a denial of service. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Oracle UEK 6 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Oracle UEK 6是美国甲骨文(Oracle)公司的一种 Oracle 构建并通过 Oracle Linux Support 提供支持的 Linux 内核。 Oracle UEK 6 中存在资源管理错误漏洞,该漏洞源于 UEK6 U3 中的代码缺少适当的文件描述符计数。 这导致了一个使用计数错误,它允许一个套接字的文件描述符在内核的另一部分仍在使用时被关闭和释放。 具有本地访问权限的攻击可以对套接字进行操作,并导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Oracle CorporationOracle Linux Oracle Linux: 7 -

II. Public POCs for CVE-2022-21504

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-21504

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2022-21504

No comments yet


Leave a comment